Junglewise Threat Intelligence

CVE-2026-24237: NVIDIA NVTabular improper deserialization

CVE-2026-24237 · Severity: high · CVSS 7.8 · Published 2026-06-02

Vendors: Nvidia.

Executive brief

NVIDIA NVTabular, a feature engineering and preprocessing library for deep learning, contains a security flaw in how it handles data files. An attacker with local access to a system could use a specially crafted file to take control of the application. This could result in the theft of sensitive information, unauthorized data modification, or the ability to run malicious commands on the affected machine.

Technical details

A deserialization vulnerability (CWE-502) exists in NVIDIA NVTabular due to the improper handling of untrusted data during object reconstruction. An attacker with local access and low privileges can exploit this by providing a maliciously crafted serialized object to the library. If processed, this can lead to arbitrary code execution in the context of the application, as well as unauthorized data modification or information disclosure. The vulnerability is tracked as CVE-2026-24237 and has a CVSS 3.1 base score of 7.8.

Affected products

  • NVIDIA NVTabular

Timeline

  • 2026-06-02: disclosed
  • 2026-06-02: advisory

References

Related threats